Odaily Planet Daily News SlowMist Security Team issued a warning that the North Korean Lazarus hacker group is using a new stealing Trojan called OtterCookie to launch targeted attacks against cryptocurrency and financial practitioners.
The attack methods include faking high-paying job interviews/investor negotiations, using deep fake videos to impersonate recruiters, and disguising malware as "programming test questions" or "system update packages."
The stolen targets include login credentials saved by browsers, passwords and digital certificates in macOS keychains, and encrypted wallet information and private keys.
SlowMist recommends being vigilant about unsolicited job/investment invitations, requiring multiple verifications for remote interviews, and never running executable files of unknown origin, especially so-called "technical test questions" or "update patches", strengthening terminal protection (EDR), deploying antivirus software and regularly troubleshooting abnormal processes.